Short answer: the DPDP Rules were notified on 13 November 2025. The Data Protection Board exists now. Consent manager provisions commence 13 November 2026. Almost everything else that imposes an obligation on your business — notice, consent, security safeguards, breach reporting, data principal rights — commences 13 May 2027.
Much of the DPDP material online was written while the Rules were still in draft, and reads as though nothing is settled. That is no longer the position. The dates below are the notified ones.
Where the law actually stands
| Phase | From | What commences |
|---|---|---|
| Immediate | 13 Nov 2025 | Rules 1, 2 and 17–21 — constitution and functioning of the Data Protection Board, appointments, inquiry procedure |
| 12 months | 13 Nov 2026 | Rule 4 — registration and obligations of consent managers |
| 18 months | 13 May 2027 | Rules 3, 5–16, 22, 23 — notice, consent, security safeguards, breach notification, children's data, Significant Data Fiduciary obligations, data principal rights, cross-border transfer |
Two implications people miss.
First, the Board is already operational. The institutional machinery was brought into force immediately, ahead of the obligations it will eventually enforce. The enforcement body exists before the duties bite.
Second, there is no grace period built into the design. The eighteen months is the transition window. A company that starts in early 2027 is not starting early.
As of this writing, roughly nine months remain before the substantive obligations commence.
Does it apply to us?
Almost certainly, if you process personal data in digital form.
There is no turnover threshold, no headcount threshold and no sector gate in the Act. If you hold an employee database, a customer or client list, vendor contact details, CCTV footage tied to identifiable people, or a website form that collects enquiries, you are processing digital personal data and you are a Data Fiduciary in respect of it.
What varies with size and risk is not whether the law applies but how much is proportionate — and whether the Central Government notifies you as a Significant Data Fiduciary, which adds a further layer.
For a professional services firm, a trading business or a small manufacturer, the practical scope is usually narrower than feared: employees, customers, vendors, and whatever a website collects. For anyone running a consumer app, a healthcare or education service, or a business built on customer data, it is considerably wider.
What full compliance requires
From 13 May 2027, the substantive obligations include:
- Notice — a clear, standalone statement to the individual of what personal data is collected, the purpose, and how to withdraw consent or complain. Notice buried inside general terms and conditions does not meet the standard.
- Consent — free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and as easy to withdraw as it was to give. Pre-ticked boxes and bundled consent do not qualify.
- Purpose limitation and data minimisation — collect only what is necessary for the stated purpose, and use it only for that purpose.
- Retention and erasure — delete personal data once the purpose is served, unless retention is required by another law. This is the obligation that most often collides with existing practice, because businesses tend to retain indefinitely by default.
- Reasonable security safeguards — an express obligation, and the one carrying the highest penalty ceiling.
- Breach notification — intimation to the Board and to affected data principals, with detailed particulars to follow within the short window the Rules prescribe (commonly cited as 72 hours). This requires a rehearsed process, not an intention.
- Data principal rights — access, correction, erasure, grievance redressal and nomination, each needing an actual mechanism and a named point of contact.
- Processor contracts — processing through a vendor must be under a valid contract, which means reviewing agreements with payroll providers, cloud services, CRM platforms and analytics tools.
- Children's data — verifiable parental consent, and no tracking, behavioural monitoring or targeted advertising directed at children.